BTCE | 5th Sem
DPDS SubjectUnit 1

DPDS Unit 1: Complete Concept Guide

Unit 1: Introduction to Data Security -> Generated and Prepared By Thiruselvan (ThiruXD)

TABLE OF CONENT

PART 1: INTRODUCTION TO DATA SECURITY

  • 1.1 Evolution of Data Security
    • Historical Timeline (1950s-1980s → 1990s → Today)
  • 1.2 Why Data Security Matters Today
    • Financial Impact
    • Cybercrime Damages
    • Scale of Exposure
    • Human Factor
  • 1.3 Security as a Multidimensional Problem
    • Governance, Legal, Ethical, and Business Continuity Dimensions
    • Consequences of Security Failures

PART 2: INFORMATION SECURITY PRINCIPLES

  • 2.1 The CIA Triad
    • Confidentiality (C)
    • Integrity (I)
    • Availability (A)
  • 2.2 Extended Security Principles
    • Authentication
    • Authorization
    • Non-Repudiation
    • Accountability
    • Privacy
    • Authenticity
    • Resilience
    • Least Privilege

PART 3: SECURITY FRAMEWORKS

  • 3.1 AAA Framework
    • Authentication (Who are you?)
    • Authorization (What can you do?)
    • Accounting/Auditing (What did you do?)
  • 3.2 Defense in Depth: Layered Security
    • Layer 1: Physical Security
    • Layer 2: Perimeter Security
    • Layer 3: Network Security
    • Layer 4: Endpoint Security
    • Layer 5: Application Security
    • Layer 6: Data Security
    • Layer 7: User and Identity
    • Layer 8: Administrative Controls

PART 4: SECURITY POLICIES

  • 4.1 Enterprise Security Policy (ESP)
    • Definition
    • Why Organizations Need Security Policies
  • 4.2 Core Elements of Security Policy
    • Purpose Statement
    • Scope
    • Policy Statements
    • Roles and Responsibilities
    • Compliance and Enforcement
    • Exceptions Process
    • Review and Update Schedule
    • Definitions
    • References
    • Approval and Signatures
  • 4.3 Security Policy Types
    • Acceptable Use Policy (AUP)
    • Information Classification Policy
    • Access Control Policy
    • Password Policy
    • Remote Access Policy
    • Incident Response Policy
    • Data Retention and Disposal Policy
    • Third-Party/Vendor Security Policy
    • Bring Your Own Device (BYOD) Policy
    • Physical Security Policy
  • 4.4 The Policy Lifecycle
    • Draft → Review → Approval → Publish and Communicate → Enforce and Monitor → Review and Update → Retire
  • 4.5 Policy Taxonomy
    • Four-Level Security Documentation Hierarchy
      • L1: Policies (The Authority Layer)
      • L2: Standards (The Specification Layer)
      • L3: Procedures (The Operational Layer)
      • L4: Guidelines (The Recommendation Layer)
  • 4.6 Additional Policy Taxonomy Categories
    • Regulatory Policies
    • Advisory Policies
    • Informative Policies
    • Technical Policies
    • Operational Policies

PART 5: DATA BREACH

  • 5.1 Definition
  • 5.2 Cyber Kill Chain Framework
    • Stage 1: Reconnaissance
    • Stage 2: Weaponization
    • Stage 3: Delivery
    • Stage 4: Exploitation
    • Stage 5: Installation
    • Stage 6: Command & Control (C2)
    • Stage 7: Actions on Objectives
  • 5.3 Attack Vectors
    • Phishing / Social Engineering
    • Stolen/Compromised Credentials
    • Vulnerabilities/Exploits
    • Insider Threats
    • Third-Party/Supply Chain
    • Physical Access

PART 6: DATA REMANENCE

  • 6.1 Definition
    • Why Deleted Data is Not Gone
    • Formatting Does NOT Destroy Data
  • 6.2 Data Remanence Categories
    • Magnetic Remanence
    • Flash Remanence
    • RAM Remanence (Cold Boot Attack)
    • Cloud and Virtualized Storage
    • Backup and Archive Copies
    • File System Artifacts
  • 6.3 Data Destruction Standards
    • Sanitization Methods
      • Clearing
      • Purging
      • Destroying

PART 7: DATA THEFT

  • 7.1 Definition
  • 7.2 Data Theft Categories
    • External Cyber Attacks
    • Insider Theft (Malicious)
    • Insider Negligence
    • Physical Theft
    • Corporate Espionage
  • 7.3 Data Loss Prevention (DLP)
    • DLP Data States
      • Data in Use
      • Data in Motion
      • Data at Rest
    • DLP Enforcement Actions
  • 7.4 Data Theft Prevention Controls
    • Access Control
    • Data Classification
    • Encryption
    • Endpoint Security
    • Network Controls
    • User Behavior Analytics (UEBA)
    • Physical Security
    • Employee Lifecycle Management
    • Security Awareness
    • Monitoring and Auditing

PART 8: WIRELESS IDENTITY THEFT

  • 8.1 Definition
    • Technologies at Risk
    • Common Objectives
  • 8.2 Types of Wireless Identity Theft
    • RFID Attacks
    • NFC Attacks
    • Wi-Fi Attacks
    • Bluetooth Attacks
    • Mobile Attacks
    • IoT Attacks
    • Real-World Impact
  • 8.3 RFID & NFC Vulnerabilities
    • RFID Risks
    • NFC Risks
  • 8.4 Specific Attack Techniques
    • Man-in-the-Middle (MITM)
    • Evil Twin Attack
    • Other Techniques

PART 9: KEY TAKEAWAYS

  • Summary Checklist

PART 10: COMPLIANCE REFERENCES

  • Key Regulations
    • GDPR
    • HIPAA
    • CCPA
    • PCI DSS
    • SOX

PART 1: INTRODUCTION TO DATA SECURITY

1.1 Evolution of Data Security

Historical Timeline

PeriodFocusCharacteristics
1950s-1980sPhysical SecurityProtection of hardware; mainframes in locked rooms
1990sPerimeter SecurityFirewalls, intrusion detection, antivirus; rise of networked systems
TodayEmbedded SecurityCloud computing, mobile devices, IoT, big data; security integrated into every layer

Why Data Security Matters Today

  • Financial Impact: Average global cost of data breach = USD 4.45 million (IBM 2023)
  • Cybercrime Damages: Projected USD 10.5 trillion annually (2025)
  • Scale of Exposure: Over 6 billion records exposed in 2021 alone
  • Human Factor: Approximately 82% of breaches involve human error (Verizon DBIR 2023)

Security as a Multidimensional Problem

Security is NOT purely a technical problem — it is a governance, legal, ethical, and business continuity problem

Consequences of Security Failures:

  • Financial penalties
  • Reputational damage
  • Loss of customer trust
  • Regulatory fines
  • In critical sectors (healthcare, energy): can endanger lives

PART 2: INFORMATION SECURITY PRINCIPLES

2.1 The CIA Triad

The foundational model for information security policy development and risk analysis.

PrincipleDefinitionMechanisms
Confidentiality (C)Ensuring information is accessible ONLY to those authorized to access it• Encryption• Access Control• Data Classification• Steganography
Integrity (I)Safeguarding accuracy and completeness of information and processing methods• Cryptographic Hashing• Digital Signatures• MACs (Message Authentication Codes)• Version Control & Audit Trails• File Integrity Monitoring (FIM)
Availability (A)Ensuring authorized users have reliable access to information and systems when needed• Redundancy & Failover• Load Balancing• Backups & Disaster Recovery• DDoS Mitigation• Uptime SLAs

2.2 Extended Security Principles

PrincipleDescriptionSignificance
AuthenticationVerifying identity of users, systems, or processesMethods: passwords, MFA, biometrics, PKI certificates. Prevents unauthorized access by imposters
AuthorizationDetermining what an authenticated user is permitted to doEnforced via RBAC, ABAC (Attribute-Based Access Control), access control lists
Non-RepudiationEnsuring a party cannot deny having performed an actionAchieved through digital signatures and audit logs. Critical in legal and financial contexts
AccountabilityHolding individuals responsible for their actionsMaintaining detailed audit trails. Logs must be tamper-proof and time-stamped
PrivacyThe right of individuals to control how their personal data is collected and usedGoverned by regulations (GDPR, HIPAA). Goes beyond security into ethics and law
AuthenticityConfirming data comes from a genuine, trusted sourceEnforced via digital certificates and signature verification
ResilienceAbility of a system to withstand attacks and continue operating in a degraded but functional stateGoes beyond recovery to proactive fault tolerance
Least PrivilegeUsers and systems should have the minimum level of access required to perform their functionsLimits the damage any compromised account can cause

PART 3: SECURITY FRAMEWORKS

3.1 AAA Framework

Authentication, Authorization, Accounting

🔐 Authentication (Who are you?)

Verifying identity through Multi-Factor Authentication (MFA) :

Factor TypeExamples
Something you knowPassword, PIN
Something you haveHardware token, smart card
Something you areBiometric: fingerprint, iris scan, facial recognition

🔑 Authorization (What can you do?)

After authentication, a policy engine checks:

  • What resources the authenticated user is allowed to access
  • What actions they can perform

📝 Accounting/Auditing (What did you do?)

  • Every login attempt, file access, configuration change, and network connection is logged
  • Audit logs = foundation of forensics and compliance

3.2 Defense in Depth: Layered Security

“Implement multiple layers of control - Even if one layer fails, others still protect the system”

LayerControls
Layer 1: Physical SecurityFences, security guards, CCTV, biometric door locks, server room access controls
Layer 2: Perimeter SecurityFirewalls, IDS/IPS, DMZ architecture
Layer 3: Network SecurityVLANs, network segmentation, encrypted protocols (TLS, IPSec, SSH)
Layer 4: Endpoint SecurityAntivirus, EDR, host-based firewalls, disk encryption
Layer 5: Application SecuritySecure coding practices, WAF, input validation, API security
Layer 6: Data SecurityEncryption at rest and in transit, DLP, data classification, rights management
Layer 7: User and IdentityMFA, SSO, PAM, security awareness training
Layer 8: Administrative ControlsSecurity policies, procedures, audits, incident response plans

PART 4: SECURITY POLICIES

4.1 Enterprise Security Policy (ESP)

Definition: A formal, management-approved document that defines an organization’s approach to protecting its information assets.

The highest-level security document that provides the foundation for all other security documents (standards, procedures, guidelines)

Why Organizations Need Security Policies?

ReasonExplanation
Legal and Regulatory ComplianceLaws such as GDPR, HIPAA, and CCPA require documented security practices. Without policies, compliance cannot be demonstrated
ConsistencyEnsure all employees, contractors, and vendors handle data consistently, reducing human-error breaches
AccountabilityEstablish clear responsibilities so in the event of a breach, it’s clear who was responsible for which control
Risk ManagementMechanism by which management formally accepts, mitigates, transfers, or avoids risk
Security CultureWell-communicated policies build a culture of security awareness across the organization

4.2 Core Elements of Security Policy

Policy ElementDescription
Purpose StatementWhy does this policy exist? What risk or compliance requirement does it address?
ScopeWho and what does the policy apply to? (All employees, contractors, vendors; all systems, or specific data types?)
Policy StatementsThe specific rules, requirements, and prohibitions. Written in clear, unambiguous language
Roles and ResponsibilitiesWho is responsible for enforcing the policy? (CISO, IT Security team, system owners, employees)
Compliance and EnforcementWhat are the consequences of non-compliance? (Disciplinary action, termination, legal prosecution)
Exceptions ProcessHow can exceptions to the policy be requested and approved?
Review and Update ScheduleHow frequently is the policy reviewed? (Typically annually, or after a significant security event)
DefinitionsClear definitions of technical terms used in the policy
ReferencesRelated policies, standards, laws, and regulations that this policy is aligned with
Approval and SignaturesManagement approval (typically CISO, CIO, or CEO sign-off) gives the policy authority

4.3 Security Policy Types

Policy TypeCoverage
Acceptable Use Policy (AUP)Rules for acceptable and prohibited use of company systems, email, internet, and devices
Information Classification PolicyFramework for classifying data by sensitivity (Public, Internal, Confidential, Restricted) and handling rules for each
Access Control PolicyRules for granting, managing, reviewing, and revoking access to systems and data
Password PolicyMinimum password length, complexity, expiry, reuse, and multi-factor authentication requirements
Remote Access PolicyRequirements for VPN usage, endpoint security for remote workers, and split tunneling rules
Incident Response PolicyProcedures for detecting, reporting, containing, investigating, and recovering from security incidents
Data Retention and Disposal PolicyHow long data must be kept, how it must be securely deleted, and what destruction standards apply
Third-Party/Vendor Security PolicySecurity requirements that vendors and partners must meet to access organizational data or systems
Bring Your Own Device (BYOD) PolicyRules for using personal devices for work, including MDM enrollment, encryption, and remote wipe capability
Physical Security PolicyControls for physical access to facilities, server rooms, and equipment

4.4 The Policy Lifecycle

A security policy is not a static document - Follows a lifecycle:

  1. Draft: Security team drafts the policy based on risk assessment and compliance requirements
  2. Review: Legal, HR, IT, and business unit stakeholders review the draft
  3. Approval: Executive management (CISO/CIO/CEO) formally approves the policy
  4. Publish and Communicate: Policy is distributed to all affected parties. Training is conducted
  5. Enforce and Monitor: Compliance is monitored through audits, technical controls, and user reporting
  6. Review and Update: Policy is reviewed at scheduled intervals and updated when threats, technology, or regulations change
  7. Retire: Policies that are no longer relevant are formally retired and replaced

4.5 Policy Taxonomy

Definition: Systematic classification and organization of security documents into a coherent hierarchy.

A well-defined taxonomy ensures that every security requirement is documented at the appropriate level of detail and authority. There are no gaps or contradictions between documents.

Four-Level Security Documentation Hierarchy

LevelDocument TypeCharacteristicsExample
L1POLICIESHighest authority, management-approved, broad and general. State what MUST be done. Rarely change.“All data at rest must be encrypted”
L2STANDARDSMore specific than policies, define measurable requirements. State HOW MUCH or HOW WELL.“Encryption must use AES-256 or higher”
L3PROCEDURESStep-by-step instructions for implementing a policy or standard. Operational, detailed, role-specific.“Step 1: Install BitLocker. Step 2: Enable AES-256…”
L4GUIDELINESRecommended (not mandatory) best practices. Provide flexibility.“It is recommended to store encryption keys in a separate HSM”

Standards: The Specification Layer

  • Translate policy intent into specific, measurable requirements
  • Define minimum acceptable security configurations, algorithms, key length protocols
  • Mandatory and specific, but less frequent in change than procedures
  • Reference to external standards (ISO 27001, NIST SP 800-53, PCI DSS)
  • Written for a technical audience and contain technical specifications

Example Standard Statement:

“Encryption of data at rest on portable devices must use AES-256 in CBC or GCM mode. Key management must use FIPS 140-2 validated hardware security modules (HSMs). Encryption keys must be rotated every 12 months.”

Policies: The Authority Layer

  • The strategic layer of security documentation
  • Express management’s intent and commitment to security
  • Written in simple, non-technical language accessible to all employees
  • Have long lifespans (years) and change only when business strategy or regulatory environment changes significantly
  • Typically 1-5 pages in length — concise and broad
  • Carry the weight of organizational authority — violation can result in disciplinary action

Example Policy Statement:

“All company data classified as Confidential or Restricted must be encrypted using approved algorithms when stored on any portable device.”

Procedures: The Operational Layer

  • Day-to-day operational instructions that tell employees exactly how to perform security-related tasks
  • Step-by-step, sequential, and role-specific
  • Include who does what, when, and with which tools
  • Change frequently as technology and processes evolve
  • Primary document used during audits and compliance reviews to demonstrate implementation

Example: Patch Management Procedure:

  1. Monitor vendor security advisories daily
  2. Classify patches as Critical / High / Medium / Low
  3. Test Critical patches in the staging environment within 24 hours
  4. Deploy Critical patches to production within 72 hours
  5. Document patching in the ITSM ticketing system
  6. Verify patch success and update asset inventory

Guidelines: The Recommendation Layer

  • Non-mandatory recommendations that help employees make good security decisions
  • Provide flexibility in implementation while still promoting best practices
  • Particularly useful in areas that are rapidly evolving (e.g., AI/ML security)
  • Cannot be used as the basis for disciplinary action if not followed

Example:

“It is recommended that employees use a password manager to generate and store complex, unique passwords for each service, rather than creating passwords manually.”


4.6 Additional Policy Taxonomy Categories

CategoryDescription
Regulatory PoliciesDerived from legal requirements (GDPR, HIPAA, SOX). Mandatory compliance; non-compliance results in regulatory penalties
Advisory PoliciesStrongly recommended practices that, while not mandatory, are expected to be followed in most circumstances
Informative PoliciesEducational in nature; designed to inform employees about security risks and best practices without mandating specific actions
Technical PoliciesGovern specific technical controls (e.g., firewall configuration policy, cryptography policy, software development lifecycle policy)
Operational PoliciesGovern day-to-day security operations (e.g., incident response policy, change management policy, log review policy)

PART 5: DATA BREACH

5.1 Definition

Data Breach: An incident in which unauthorized individuals gain access to sensitive, protected, or confidential data, potentially exposing it to unauthorized parties.

Key Insight: Most significant data breaches are not instantaneous events — they are deliberate campaigns that unfold over days, weeks, or even months.


5.2 Cyber Kill Chain Framework

Developed by Lockheed Martin - 7 Stages of a Data Breach

StageAttacker ActivityDefensive Opportunity
1. ReconnaissanceAttacker gathers information about the target: employee names, email formats, IP ranges, technologies in use, social media profiles, job postings (which reveal technologies used). Tools: OSINT (Maltego, Shodan), LinkedIn, Google DorkingMinimize public exposure, monitor for scanning activity, employee awareness of social engineering
2. WeaponizationAttacker creates or acquires a weapon: malware payload (ransomware, RAT, keylogger), exploit code for a known vulnerability, phishing email templatePatch known vulnerabilities promptly (reducing exploitable attack surface), use email security gateways to filter malicious attachments
3. DeliveryAttacker delivers the weapon to the target: phishing email with malicious attachment or link, drive-by download via compromised website, USB drop, supply chain compromiseEmail filtering, web proxies, user awareness training, endpoint protection
4. ExploitationThe weapon executes: user clicks phishing link and malware runs, browser exploit fires, SQL injection extracts credentialsPatch management, application whitelisting, EDR, secure coding
5. InstallationAttacker establishes persistence: installs backdoor, creates rogue admin account, modifies startup scripts, injects into legitimate processesFile integrity monitoring, privileged access management, behavioral analytics (UEBA)
6. Command & Control (C2)Attacker communicates with the compromised system: establishes encrypted C2 channel (often using legitimate protocols like HTTPS, DNS to blend in), receives instructions, downloads additional toolsNetwork traffic analysis, DNS monitoring, proxy inspection of HTTPS traffic
7. Actions on ObjectivesAttacker achieves their goal: exfiltrates sensitive data, deploys ransomware, destroys data, pivots to other systems, establishes long-term presenceDLP, network segmentation, data classification, anomaly detection for large outbound data transfers

5.3 Attack Vectors

Understanding the primary vectors through which breaches are initiated allows organizations to prioritize defensive investments.

Attack VectorFrequency / ExamplesDefenses
Phishing / Social Engineering31% of breaches (Verizon DBIR 2023). Spear phishing, BEC (Business Email Compromise), vishing (voice phishing), smishing (SMS phishing)Email security, DMARC/SPF/DKIM, security awareness training, phishing simulations
Stolen/Compromised Credentials49% of breaches. Password reuse, credential stuffing, dark web credential purchasesMFA, Password Manager, PAM, monitoring dark web for exposed credentials
Vulnerabilities/Exploits26% of breaches. Unpatched systems, zero-day exploits, misconfigured cloud servicesPatch management, vulnerability scanning, security configuration management
Insider Threats19% of breaches (Ponemon 2022). Malicious insiders (data theft, sabotage), negligent insiders (mistakes, policy violations), compromised insiders (credential theft)Least privilege, UEBA, DLP, background checks
Third-Party/Supply ChainGrowing vector - 62% of network intrusions via partner exploitation. Software supply chain (SolarWinds, Log4Shell). Service provider access abuseThird-party risk management, vendor security assessments, supply chain transparency
Physical AccessOften underestimated. Stolen laptops/devices, tailgating into secure areas, dumpster diving, evil maid attacksFull disk encryption, physical security controls, clean desk policy

PART 6: DATA REMANENCE

6.1 Definition

Data Remanence: Residual representation of digital data that persists on a storage medium after attempts to erase or delete it.

Critical Insight: ‘Deleted’ data is frequently recoverable using forensic techniques — posing a significant security risk when storage media is repurposed, donated, sold, or disposed of.

Why Deleted Data is Not Gone?

When a file is ‘deleted’ in most operating systems:

  1. The operating system removes the directory entry (file name and metadata are removed from the file system table)
  2. Marks the storage blocks previously occupied by the file as ‘available’ for future use
  3. Actual data remains physically on the disk until those blocks are overwritten by new data

Freely available tools (Recuva, TestDisk, PhotoRec, FTK, EnCase), forensic investigators — or attackers — can recover this ‘deleted’ data trivially.

Formatting Does NOT Destroy Data

Format TypeWhat It DoesData Destruction Level
Quick FormatRewrites the file system structureMinimal - Data easily recoverable
Full FormatOverwrites each sector with zerosMore thorough, but may still leave traces recoverable by advanced laboratory techniques

6.2 Data Remanence Categories

Magnetic Remanence

  • Laboratory tools can read a “magnetic shadow” of overwritten data on old hard drives
  • Modern high-density drives make this recovery almost impossible in practice
  • While technically a risk, it is highly impractical on modern hardware

Flash Remanence

  • SSDs move data around to extend the drive’s lifespan
  • Overwriting a specific file leaves the old data hidden in spare storage cells
  • Traditional file deletion and overwriting do not completely wipe SSDs

RAM Remanence (Cold Boot Attack)

  • Freezing DRAM with liquid nitrogen keeps data active for minutes after power-off
  • Attackers with physical access can extract encryption keys and passwords
  • Proven, real-world attack technique, not just a theory

Cloud and Virtualized Storage

  • New tenants can access leftover data from previous users
  • Poor storage wiping during user reallocation
  • Providers use encryption and data overwriting to block access

Backup and Archive Copies

  • Deleted files often live on in backup tapes and archive systems
  • Strict retention policies are missing or not properly enforced
  • Automated deletion rules must target every single backup copy

File System Artifacts

File system journals, log files, swap files, print spoolers, browser cache, and system restore points may contain fragments of ‘deleted’ data.


6.3 Data Destruction Standards

Purpose: Provide organizations with authoritative, recognized methods for permanently removing sensitive data from storage media at end-of-life.

Essential for Compliance:

  • GDPR Article 17 — Right to Erasure
  • HIPAA safeguards
  • PCI DSS Requirement 9.8.2
  • Preventing data remanence exploits

Sanitization Methods

Sanitization MethodDescriptionApplicable When
ClearingOverwrites data with zeros using standard software commandsInternal reuse - Media stays inside the organization
PurgingBlock lab level recovery via secure erase, crypto-erase, or degaussingExternal release - Media is being sold, donated, or traded in
DestroyingPhysically shreds, melts, or incinerates the storage mediaClassified data - End-of-life media leaving company custody

PART 7: DATA THEFT

7.1 Definition

Data Theft: Unauthorized taking, copying, or transfer of confidential, sensitive, or proprietary information from an organization or individual.

Key Insight: Unlike traditional theft, data theft often leaves the original data intact — making it difficult to detect.

Perpetrators may be:

  • External attacker
  • Malicious insider
  • Business competitor engaged in corporate espionage

7.2 Data Theft Categories

CategoryDescriptionExamples
External Cyber AttacksRemote attackers exploiting vulnerabilities, stolen credentials, malware, ransomware, or supply chain compromise to exfiltrate dataAPT groups, ransomware gangs, hacktivist groups
Insider Theft (Malicious)Employees, contractors, or privileged users deliberately stealing data for financial gain, competitive advantage, espionage, or revengeA departing employee exfiltrating customer database to a competitor
Insider NegligenceEmployees accidentally exposing data through misconfiguration, sending data to wrong recipients, using unapproved cloud services (Shadow IT), or losing devicesThe majority of ‘insider incidents’ are negligent rather than malicious
Physical TheftStealing physical devices (laptops, smartphones, USB drives, printed documents) that contain unencrypted sensitive dataA laptop stolen from an airport lounge containing unencrypted patient records
Corporate EspionageCompetitors or nation-state actors systematically stealing intellectual property, trade secrets, research data, or strategic plansInvolves sophisticated, long-duration campaigns

7.3 Data Loss Prevention (DLP)

The Primary Technical Defense

Definition: Set of tools and processes that monitor, detect, and block unauthorized movement of sensitive data.

DLP Data States

Data StateHow DLP Protects
Data in UseDLP agent monitors clipboard operations, print jobs, screenshot attempts, and USB data transfers on endpoint devices
Data in MotionDLP proxy or email gateway inspects network traffic (email, web uploads, FTP) for sensitive content (credit card numbers, SSNs, health records) using content inspection
Data at RestDLP discovers and classifies sensitive data stored in file servers, databases, cloud storage, and endpoints, flagging improperly stored sensitive data

DLP Enforcement Actions

  • Alert
  • Block
  • Quarantine
  • Encrypt
  • User Notification
  • Require Justification

7.4 Data Theft Prevention Controls

Control CategorySpecific Controls
Access ControlLeast-privilege access model. Role-Based Access Control (RBAC). Privileged Access Management (PAM). Just-In-Time access. Regular access reviews and certification
Data ClassificationClassify all data by sensitivity. Apply handling requirements per classification. Use automated classification tools (Microsoft Purview, Varonis)
EncryptionEncrypt all sensitive data at rest and in transit. Full disk encryption on all endpoints. Rights Management (IRM/DRM) for document-level protection
Endpoint SecurityDLP agent on all endpoints. USB port control (block or allow list). Application whitelisting. Endpoint Detection and Response (EDR)
Network ControlsEmail DLP gateway. Web proxy with HTTPS inspection. Firewall rules blocking unauthorized outbound connections. Network traffic analysis (NTA)
User Behavior Analytics (UEBA)Baseline normal user behavior. Alert on anomalies: bulk data downloads, access at unusual hours, access to unusual data, large file uploads to external sites
Physical SecurityFull-disk encryption for all portable devices. Remote wipe capability for lost/stolen devices. Clean desk policy. Screen privacy filters in public areas
Employee Lifecycle ManagementRevoke all access on employee termination (same-day, automated). Conduct exit interviews. Monitor departing employees for unusual data access in final weeks
Security AwarenessTrain employees on insider threat recognition. Create a security-positive culture where employees report suspicious behavior. Implement anonymous whistleblower channels
Monitoring and AuditingLog all access to sensitive data. Retain logs in tamper-proof storage. Regular log review and alerting. Periodic security audits and penetration testing

PART 8: WIRELESS IDENTITY THEFT

8.1 Definition

Wireless Identity Theft: Unauthorized theft of personal or financial information through wireless communication technologies.

Exploits radio-frequency (RF) communication without physical contact

Technologies at Risk

  • RFID cards
  • NFC payments
  • Wi-Fi networks
  • Bluetooth devices
  • IoT devices

Common Objectives

  • Identity theft
  • Financial fraud
  • Account takeover
  • Unauthorized access

8.2 Types of Wireless Identity Theft

TechnologyCommon AttackExample
RFIDSkimming, CloningReading contactless cards
NFCMalicious NFC tagsFake payment requests
Wi-FiEvil Twin, MITMFake public Wi-Fi hotspot
BluetoothBluesnarfing, BluebuggingStealing contacts/messages
MobileSIM SwappingBypassing SMS OTP
IoTData interceptionSmart wearable information theft

Real-World Impact

  • Millions of identity theft cases annually
  • Rising contactless payment fraud
  • Increasing SIM swapping attacks targeting online banking and cryptocurrency

8.3 RFID & NFC Vulnerabilities

RFID Risks

  • Eavesdropping
  • Skimming
  • Relay attacks
  • Card cloning
  • Data modification
  • Signal jamming

NFC Risks

  • Rogue NFC applications
  • Malicious NFC tags
  • Data corruption
  • Relay attacks
  • NFC phishing

Strong encryption and secure key management are essential


8.4 Specific Attack Techniques

Man-in-the-Middle (MITM)

  • Attacker secretly intercepts communication between two parties
  • Examples: SSL Stripping, ARP Poisoning, DNS Spoofing, HTTPS Spoofing, BGP Hijacking

Evil Twin Attack

  1. Create fake Wi-Fi hotspot
  2. Victim connects
  3. Traffic passes through attacker
  4. Credentials are stolen

Other Techniques

  • Wi-Fi sniffing
  • IMSI Catchers (Fake cell towers)
  • Bluetooth sniffing
  • SIM Swapping

PART 9: KEY TAKEAWAYS

Summary Checklist

ConceptKey Points
CIA TriadConfidentiality, Integrity, Availability - Foundational security model
Extended PrinciplesAuthentication, Authorization, Non-Repudiation, Accountability, Privacy, Authenticity, Resilience, Least Privilege
AAA FrameworkAuthentication (Who), Authorization (What), Accounting/Auditing (What did they do?)
Defense in Depth8 layers: Physical → Perimeter → Network → Endpoint → Application → Data → User/Identity → Administrative
Security PoliciesEnterprise Security Policy (ESP), Policy lifecycle, 4-level taxonomy
Policy TaxonomyPolicies (L1) → Standards (L2) → Procedures (L3) → Guidelines (L4)
Data BreachCyber Kill Chain: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → C2 → Actions on Objectives
Attack VectorsPhishing, Credentials, Vulnerabilities, Insider Threats, Supply Chain, Physical
Data RemanenceResidual data persists after deletion. Sanitization: Clearing, Purging, Destroying
Data TheftExternal attacks, Malicious insiders, Negligence, Physical theft, Espionage
DLPProtects Data in Use, Data in Motion, Data at Rest
Wireless Identity TheftRFID, NFC, Wi-Fi, Bluetooth, Mobile, IoT attacks

PART 10: COMPLIANCE REFERENCES

Key Regulations

RegulationRelevance
GDPRData protection, right to erasure, privacy
HIPAAHealthcare data protection
CCPACalifornia consumer privacy
PCI DSSPayment card data security
SOXFinancial data integrity

On this page

TABLE OF CONENTPART 1: INTRODUCTION TO DATA SECURITYPART 2: INFORMATION SECURITY PRINCIPLESPART 3: SECURITY FRAMEWORKSPART 4: SECURITY POLICIESPART 5: DATA BREACHPART 6: DATA REMANENCEPART 7: DATA THEFTPART 8: WIRELESS IDENTITY THEFTPART 9: KEY TAKEAWAYSPART 10: COMPLIANCE REFERENCESPART 1: INTRODUCTION TO DATA SECURITY1.1 Evolution of Data SecurityHistorical TimelineWhy Data Security Matters TodaySecurity as a Multidimensional ProblemPART 2: INFORMATION SECURITY PRINCIPLES2.1 The CIA Triad2.2 Extended Security PrinciplesPART 3: SECURITY FRAMEWORKS3.1 AAA FrameworkAuthentication, Authorization, Accounting🔐 Authentication (Who are you?)🔑 Authorization (What can you do?)📝 Accounting/Auditing (What did you do?)3.2 Defense in Depth: Layered SecurityPART 4: SECURITY POLICIES4.1 Enterprise Security Policy (ESP)Why Organizations Need Security Policies?4.2 Core Elements of Security Policy4.3 Security Policy Types4.4 The Policy Lifecycle4.5 Policy TaxonomyFour-Level Security Documentation HierarchyStandards: The Specification LayerPolicies: The Authority LayerProcedures: The Operational LayerGuidelines: The Recommendation Layer4.6 Additional Policy Taxonomy CategoriesPART 5: DATA BREACH5.1 Definition5.2 Cyber Kill Chain Framework5.3 Attack VectorsPART 6: DATA REMANENCE6.1 DefinitionWhy Deleted Data is Not Gone?Formatting Does NOT Destroy Data6.2 Data Remanence CategoriesMagnetic RemanenceFlash RemanenceRAM Remanence (Cold Boot Attack)Cloud and Virtualized StorageBackup and Archive CopiesFile System Artifacts6.3 Data Destruction StandardsSanitization MethodsPART 7: DATA THEFT7.1 Definition7.2 Data Theft Categories7.3 Data Loss Prevention (DLP)DLP Data StatesDLP Enforcement Actions7.4 Data Theft Prevention ControlsPART 8: WIRELESS IDENTITY THEFT8.1 DefinitionTechnologies at RiskCommon Objectives8.2 Types of Wireless Identity TheftReal-World Impact8.3 RFID & NFC VulnerabilitiesRFID RisksNFC Risks8.4 Specific Attack TechniquesMan-in-the-Middle (MITM)Evil Twin AttackOther TechniquesPART 9: KEY TAKEAWAYSSummary ChecklistPART 10: COMPLIANCE REFERENCESKey Regulations